Data Protection and Privacy 2025

INDONESIA TRENDS AND DEVELOPMENTS Contributed by: Agus Ahadi Deradjat (Agung), Mahiswara Timur, Nina Cornelia Santoso and Dhan Partap Kaur (Sonia), ABNR Counsellors at Law

Data Privacy Imperatives in Business: How Indonesia’s PDP Law Has Evolved to Accommodate the AI, Healthcare and Financial Services Sectors PDP Law in a nutshell In 2022, the Indonesian Parliament passed Law No 27 of 2022 on Personal Data Protection (“PDP Law”), which is designed to serve as the overarching law on personal data protection. The PDP Law is largely modelled on the EU’s General Data Protection Regulation (GDPR), regarded as the “gold standard” for personal data protection worldwide, thus demonstrating further effort by the Indonesian government to bring data protec - tion into line with the industry standard. In addition to the PDP Law, several existing laws and regulations related to personal data protection remain in force, provided that they do not conflict with the PDP Law. Accordingly, the implementation of personal data protection is subject to the following laws and regulations: • PDP Law; • Law No 11 of 2008 on Electronic Information and Transactions, last amended by Law No 1 of 2024 (“EIT Law”); • Government Regulation No 71 of 2019 on the Provision of Electronic Systems and Transac - tions (“GR 71/2019”); and • other sector-specific regulations. The PDP Law has extraterritorial effect, meaning that overseas organisations, including individu - als, public entities, and international organisa - tions, can be prosecuted in Indonesia for violat - ing the Law, particularly for non-compliance in processing personal data of Indonesian citizens, whether onshore or offshore. The Law, which officially ended its two-year grace period, was enacted on 17 October 2024. Since then, the Indonesian government has been working on the

Draft Implementing Regulation for Law No 27 of 2022 on Personal Data Protection (“Draft GR PDP”), which is intended to provide further guid - ance on the Law’s implementation and enforce - ment. However, as of early 2025, there is no clear timeline for its finalisation. Some of the notable provisions under the PDP Law include the following. Types of personal data The PDP Law defines “personal data” as “any data related to an individual (natural person), whether identified or capable of being identified independently or in combination with other infor - mation, whether directly or indirectly, through the use of an electronic system and/or non-electron - ic means.” The individual is referred to as a “data subject”. The PDP Law further categorises personal data as general personal data (name, gender, nation - ality, religion, marital status, or personal data that together can identify a person) and specific per - sonal data (data on health, biometric or genetic, and criminal records; data on children; financial data; and/or other data in accordance with the laws and regulations). There is no particular dif - ferentiation in treatment of the processing of general or specific personal data. However, the processing of specific personal data would trig - ger additional obligations, such as the need to perform a Data Protection Impact Assessment (DPIA) and appoint a Data Protection Officer (DPO). Data controller and data processor The PDP Law expressly differentiates between “data controller” and “data processor”, which is a new concept under Indonesian laws. A data controller determines the purpose of, and con - trols, the personal data processing. A data pro -

212 CHAMBERS.COM

Powered by